# How WinDivert Driver Functions as a Kernel-Level Filter on Windows

> Discover how the WinDivert driver functions as a kernel-level network filter on Windows. Learn how it intercepts and manages network packets for deeper control.

- Repository: [Flowseal/zapret-discord-youtube](https://github.com/Flowseal/zapret-discord-youtube)
- Tags: internals
- Published: 2026-05-02

---

**WinDivert functions as a kernel-level network filter by installing a signed driver (`WinDivert64.sys`) that hooks into the Windows NDIS filter stack, intercepting packets before they reach the TCP/IP stack and routing them through a user-mode DLL for inspection, modification, or reinjection.**

The `Flowseal/zapret-discord-youtube` repository utilizes WinDivert to implement transparent packet filtering for circumventing network censorship. Unlike user-mode networking APIs such as Winsock, WinDivert operates at the kernel level, enabling it to capture and manipulate traffic generated by system services and other drivers that would otherwise remain invisible to standard applications.

## Kernel-Level Packet Interception Architecture

WinDivert operates as a **callout driver** in the Windows Filtering Platform (WFP), sitting between the network interface card (NIC) driver and the TCP/IP protocol stack.

### The WinDivert64.sys Driver Component

The core filtering logic resides in `bin/WinDivert64.sys`, a signed kernel-mode driver distributed within the repository. When loaded via the Windows Service Control Manager (`sc create`), this driver attaches to the NDIS (Network Driver Interface Specification) filter chain at the **kernel level**. According to the WinDivert architecture, the driver implements `FilterSendNetBufferLists` and `FilterReceiveNetBufferLists` callbacks that receive copies of every outbound and inbound packet traversing the network stack.

### NDIS Filter Stack Integration

Once the service starts (`net start "WinDivert"`), the driver inserts itself into the network data path. For **outbound traffic**, packets flow from applications through the TCP/IP stack, hit the WinDivert filter, and are diverted before reaching the NIC driver. For **inbound traffic**, packets are intercepted immediately after processing by the NIC driver but before delivery to the TCP/IP stack. This positioning allows the driver to capture packets that bypass user-mode APIs entirely, including those generated by system services, kernel drivers, and other low-level Windows components.

## Filtering Engine and Packet Flow

WinDivert employs a **BPF-style expression language** to determine which packets to divert from the kernel flow to user-mode processing.

### BPF-Style Filter Expressions

The driver evaluates packets against filter strings such as `"outbound && ip && tcp && dst port 443"` defined during handle initialization. When a match occurs, the driver copies the packet into a **kernel-mode queue** rather than allowing it to continue normal processing. This mechanism ensures that only relevant traffic consumes resources in user mode, while non-matching packets pass through with minimal overhead.

### Packet Queue and User-Mode Interaction

The user-mode component, `bin/WinDivert.dll`, exposes functions including `WinDivertOpen`, `WinDivertRecv`, and `WinDivertSend`. Applications open a handle to the driver with a specific filter, then call `WinDivertRecv` to dequeue packets from the kernel buffer. After optional inspection or modification—such as rewriting IP headers or changing TCP ports—the application calls `WinDivertSend` to reinject the packet back into the network stack, or simply drops it by not reinjecting.

## Installation and Service Management

The repository provides `service.bat` to handle driver lifecycle management, ensuring proper registration and avoiding conflicts with existing WinDivert installations.

### Installing the Driver

The batch script registers the driver as a Windows service using the `sc` command. The following excerpt from `service.bat` (lines 204-209) demonstrates the installation process:

```batch
rem Install WinDivert driver as a service
sc create "WinDivert" binPath= "%~dp0\bin\WinDivert64.sys" type= kernel start= auto
net start "WinDivert"

```

This registration persists across reboots until explicitly removed. The `type= kernel` parameter specifies that this is a kernel-mode driver service, distinct from user-mode services.

### Removing the Driver

Cleanup operations in `service.bat` (lines 574-605) stop and delete the service:

```batch
rem Stop and delete the WinDivert service
net stop "WinDivert" >nul 2>&1
sc delete "WinDivert" >nul 2>&1

```

These commands ensure the driver unloads from memory and detaches from the NDIS filter chain, restoring normal packet flow without the interception layer.

## Practical Implementation in Zapret

The `zapret` project uses `winws.exe` (found in `bin/winws.exe`) as a lightweight wrapper that initializes the WinDivert driver and applies censorship circumvention rules.

### Driver Initialization via Batch Scripts

The `general (FAKE TLS AUTO).bat` and similar scripts invoke `winws.exe` with specific filter parameters to capture HTTPS traffic destined for blocked IP ranges. The helper executable loads `WinDivert.dll`, opens the driver with a predefined filter expression, and forwards matching packets to local proxy instances or modifies them directly to evade Deep Packet Inspection (DPI).

### Packet Modification Workflow

When `winws.exe` runs with parameters like `-p "outbound && tcp && dst port 443"`, it performs the following sequence:

1. Calls `WinDivertOpen` with the filter expression and layer specifications
2. Enters a loop calling `WinDivertRecv` to receive diverted packets
3. Examines packet headers against lists stored in `lists/*.txt` files
4. Modifies packet headers (such as fragmenting TLS Client Hello or changing TCP window sizes) to bypass detection
5. Calls `WinDivertSend` to reinject modified packets or drops them if they match blocked criteria

Because the driver is **digitally signed**, it loads on 64-bit Windows without requiring the user to disable Driver Signature Enforcement (DSE), though Windows 7 users require a specific driver variant as noted in the repository documentation.

## Summary

- **WinDivert64.sys** (`bin/WinDivert64.sys`) functions as a kernel-mode driver that hooks into the NDIS filter stack via `FilterSendNetBufferLists` and `FilterReceiveNetBufferLists` callbacks.
- **BPF-style filters** determine which packets divert to user mode, minimizing performance impact on non-target traffic.
- **service.bat** manages the driver lifecycle through Windows Service Control Manager commands (`sc create`, `net start`, `sc delete`).
- **WinDivert.dll** provides the API surface for applications to receive, modify, and reinject packets using `WinDivertRecv` and `WinDivertSend`.
- The signed driver architecture allows operation on modern 64-bit Windows systems without disabling security features, enabling transparent filtering for anti-censorship tools like `zapret`.

## Frequently Asked Questions

### What is the difference between WinDivert64.sys and WinDivert.dll?

**WinDivert64.sys** is the kernel-mode driver that performs actual packet interception in the NDIS stack, while **WinDivert.dll** is the user-mode library that applications link against to communicate with the driver. The DLL handles opening handles, receiving diverted packets, and sending modified packets, whereas the SYS file executes in kernel space with elevated privileges to access all network traffic.

### Why does WinDivert require installation as a Windows service?

Windows requires kernel-mode drivers to be registered as services through the Service Control Manager (`sc create`) to ensure proper lifecycle management, security validation, and system integration. This registration allows the operating system to verify the driver's digital signature, control loading at boot time, and ensure cleanup during shutdown through service dependencies.

### Can WinDivert capture packets from all applications, including system services?

**Yes.** Because WinDivert operates at the kernel level within the NDIS filter stack, it captures packets before they reach user-mode APIs like Winsock. This allows it to intercept traffic generated by system services, other kernel drivers, and privileged processes that would be invisible to conventional packet capture libraries running in user mode.

### Is it safe to use WinDivert on Windows 11 with driver signature enforcement enabled?

**Yes.** The `WinDivert64.sys` driver included in the repository is digitally signed with a valid Windows driver signature, allowing it to load on 64-bit Windows 10 and Windows 11 systems without disabling Driver Signature Enforcement (DSE). However, some antivirus software may flag the driver as suspicious due to its packet interception capabilities, requiring users to add an exclusion for the `bin\WinDivert64.sys` file.